Personal Data Processing
Personal data processing records the volume and sensitivity of personal and special-category data an organisation collects, stores or processes, a primary driver of breach notification duties, regulatory exposure and third-party liability.
- Category
- IT/Cyber
- Data type
- Enumeration
- Risk drivers
- Severity, Accumulation
- Underwriting impact
- Premium, Sublimit, Condition/Warranty
Typical proposal-form questions
- How many data subjects' personal data does the organisation process, and does this include special categories such as health, biometric or financial data?
- Is personal data processed on behalf of third-party clients under a data processing agreement, and what contractual liability does this create?
- What data protection safeguards (e.g. encryption at rest and in transit, access restriction, retention limits) apply to the personal data held?
Evidence
- Data inventory or record of processing activities
- Data processing agreements with clients or sub-processors
- Data protection impact assessment, where applicable
Why it matters for underwriting
The volume and sensitivity of personal data an organisation holds directly determines the scale of a potential breach: the number of affected data subjects drives notification costs, credit monitoring obligations and the size of any regulatory fine under frameworks such as the Swiss Federal Act on Data Protection or the EU General Data Protection Regulation, while the presence of special-category data such as health, biometric or financial information multiplies both the severity of harm to individuals and the likelihood of regulatory escalation. Where personal data is processed on behalf of third-party clients, a breach also exposes the insured to contractual indemnification claims and professional indemnity exposure from those clients, linking the cyber and liability lines. Underwriters use this attribute to estimate probable breach notification cost and regulatory fine exposure as core inputs to pricing and sublimit setting.
Capturing the attribute and evidence
Proposal forms ask for an estimate of the number of data subjects whose personal data is processed, whether special categories of data such as health, biometric, genetic or financial information are included, and whether data is processed on behalf of third parties under data processing agreements that may impose contractual liability beyond statutory minimums. Underwriters request the organisation’s data inventory or record of processing activities, copies of material data processing agreements with clients or sub-processors, and, for higher-risk processing activities, a data protection impact assessment documenting the safeguards applied. The technical protections in place, such as encryption at rest and in transit, role-based access restriction and defined retention periods, are assessed alongside the raw volume, since well-protected data reduces the practical severity of an underlying breach.
Effect on coverage, premium and conditions
Lower volumes of standard personal data with strong technical safeguards and clear contractual allocation of liability support standard terms and pricing. Large volumes of data subjects, particularly combined with special-category data or significant third-party processing obligations, typically drive higher premium and increased breach-response and regulatory-defence sublimits to reflect the larger potential notification population and fine exposure. Processing that lacks basic safeguards such as encryption, or contractual data processing arrangements that shift disproportionate liability onto the insured without corresponding technical or organisational controls, commonly results in a specific condition, a sublimit on third-party liability arising from processing on behalf of clients, or, in severe cases, exclusion.
Mitigation measures
Maintaining an accurate, current data inventory or record of processing activities is the foundational control, since an organisation cannot protect data it has not identified. Minimising the volume and retention period of personal and special-category data actually held, applying encryption at rest and in transit, and restricting access on a role and need-to-know basis are standard recommendations to reduce both breach likelihood and severity. Where data is processed on behalf of third parties, negotiating data processing agreements with balanced liability allocation and confirming that contractual security obligations are actually met in practice are recommended before the underlying cyber exposure can be considered adequately mitigated.
Legal basis
- CH: Bundesgesetz über den Datenschutz (Swiss Federal Act on Data Protection, FADP)